{
  "slug": "supply-chain",
  "name": "CI and dependency trust",
  "category": "Infrastructure",
  "summary": "Review build and dependency trust from source selection through a verifiable artifact and its deployment authority.",
  "scope": "Defensive study and review of artifacts supplied by their owner. Record missing evidence as an open question.",
  "inputs": [
    "Workflow definitions",
    "Lockfiles and dependency policy",
    "Build identities and artifact attestations"
  ],
  "review": [
    {
      "title": "Map trusted inputs",
      "body": "Identify source revisions, external actions, package registries, caches, and contributors that influence a build."
    },
    {
      "title": "Review execution authority",
      "body": "Confirm untrusted changes cannot inherit secrets, deployment credentials, or mutable release authority."
    },
    {
      "title": "Verify provenance",
      "body": "Link the released artifact to its source, builder, dependency resolution, and approval evidence."
    },
    {
      "title": "Constrain dependencies",
      "body": "Use explicit registries, namespace ownership, immutable versions, and reviewable lockfile changes."
    }
  ],
  "outputs": [
    "Build trust map",
    "Workflow permission review",
    "Dependency provenance record"
  ],
  "pitfalls": [
    "Assuming a repository event is trusted",
    "Using mutable build references",
    "Treating a package name as proof of ownership"
  ],
  "references": {
    "resources": [
      {
        "id": "slsa-v1-2-supply-chain-build-provenance",
        "title": "SLSA v1.2: supply-chain security and build provenance",
        "url": "https://vulns.co/research/resources/slsa-v1-2-supply-chain-build-provenance/"
      },
      {
        "id": "owasp-asvs-5-security-verification-standard",
        "title": "OWASP Application Security Verification Standard (ASVS)",
        "url": "https://vulns.co/research/resources/owasp-asvs-5-security-verification-standard/"
      },
      {
        "id": "nist-sp-800-190-container-isolation-guide",
        "title": "NIST SP 800-190: Application Container Security Guide",
        "url": "https://vulns.co/research/resources/nist-sp-800-190-container-isolation-guide/"
      }
    ],
    "diagrams": [
      {
        "id": "build-artifact-provenance-boundary",
        "title": "Build evidence must match the artifact and trusted builder",
        "url": "https://vulns.co/research/diagrams/build-artifact-provenance-boundary/"
      }
    ],
    "reports": [
      {
        "id": "angular-ci-cache-trust-2026",
        "title": "Angular automation trust and cache isolation weakness",
        "url": "https://vulns.co/research/reports/angular-ci-cache-trust-2026/"
      }
    ]
  },
  "provenance": {
    "publisher": "vulns.co / GK Data",
    "guide_updated": "2026-10-11",
    "library_as_of": "2026-10-04",
    "library_commit": "d5550c7891119cf1379e235721541c947850a3b3"
  },
  "url": "https://vulns.co/skills/supply-chain/",
  "markdown_url": "https://vulns.co/skills/supply-chain/SKILL.md"
}
